Re: session or cookie
| From: | J. Heffner | Date: | Sat, 11 Nov 2000 02:37:08 +0000 |
| Subject: | Re: session or cookie | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-24749@lists.php.net to get a copy of this message | ||
Something else to consider...some users prefer not to have to have cookies enabled. If a web site doesn't have a mechanism for handling this (a session ID), it could very well lose part of its audience.
jim
Cookies are slightly faster in that they do not hit the server as hard, but at the same time if you use large cookies they add to the amount of data that has to be downloaded, which slows things down a little.Not entirely true - I made a shopping cart (as many others have) that stored tons of info in a table. This was keyed by ONE cookie that was 32 characters long (aka a sessionID). So I don't *really* buy that.The cool thing about session variables is that there is a unique identifier to more data on the server, so the user cannot actually change the data by editing their cookie file. At the very most they could only change the identifier, which wouldn't really matter.The chances of someone altering the cookie and then stealing someone elses data is quite slim - if you seed your random sessionID well enough you shoudn't have any problems.Even with the speed issues, use session vars, they're more flexible and they add one more layer of security. :)I don't see how this is true ... I personally think session vars are for people who didn't quite understand the setcookie() function :) (this is meant as a joke - don't flame) AFAICT cookies and session id's are pretty much six one way; half a dozen the other (or 5cm one way 50mm the other for metric people)